{
  "threat_severity" : "Low",
  "public_date" : "2026-06-03T09:39:41Z",
  "bugzilla" : {
    "description" : "mina: mina: Arbitrary Code Execution via Deserialization Bypass",
    "id" : "2484326",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2484326"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-502",
  "details" : [ "ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\nAssessment: Fully addressed.\nWhen the serialised stream contains a TC_PROXYCLASSDESC (the marker \nfor a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc()\nis\ndispatched. JDK then calls the default \nObjectInputStream.resolveProxyClass(interfaces) implementation, which \nperforms Class.forName(intf, false, latestUserDefinedLoader()) for EACH \ninterface name and constructs the proxy class â€” bypassing the accepted\nclasses list .\nZDRES-233: Class.forName(name, initialize=true, classLoader) in \nreadClassDescriptor Triggers Static Initialiser of Allow-Listed Classes\nAssessment: Fully addressed.\nFor ANY class on the allow-list, deserialising a stream that names it triggers the class’s \n(static initialiser) BEFORE any instance is constructed. This means an \nattacker who supplies a class name on the allow-list (e.g., the \ndeveloper wrote accept(“com.myapp.*\") , attacker supplies \ncom.myapp.SomeClass ) causes <clinit> of SomeClass â€” and many \nreal-world classes have side-effecting static initialisers\nBoth issues have been fixed.", "A flaw was found in mina. This vulnerability involves two issues related to how the software handles serialized objects, which are objects converted into a format for storage or transmission. Firstly, a bypass in the `resolveProxyClass` method allows for the deserialization of `java.lang.reflect.Proxy` objects, which are special objects used to control access to other objects. This bypass can circumvent security filters designed to prevent malicious object deserialization. Secondly, deserializing a stream that names an allow-listed class can trigger its static initializer, a block of code that runs automatically when a class is loaded. A remote attacker could exploit these flaws to execute arbitrary code, gaining unauthorized control over the system." ],
  "statement" : "Red Hat products are affected by this vulnerability. However, the vulnerable code cannot be reached and therefore are not vulnerable. Due to this reason, this flaw has been rated with a low severity.",
  "affected_release" : [ {
    "product_name" : "OpenShift Developer Tools and Services 4.12",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60247",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.12::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628667"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.13",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60249",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.13::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786628681"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60248",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.14::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533561"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.15",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60239",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.15::el8",
    "package" : "ocp-tools-4/jenkins-rhel8:1786533565"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.16",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60251",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.16::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125166"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.17",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60246",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.17::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124635"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.18",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60250",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.18::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125069"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.19",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60252",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.19::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124632"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.20",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60259",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.20::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124925"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.21",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60254",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.21::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787125311"
  }, {
    "product_name" : "OpenShift Developer Tools and Services 4.22",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60256",
    "cpe" : "cpe:/a:redhat:ocp_tools:4.22::el9",
    "package" : "ocp-tools-4/jenkins-rhel9:1787124779"
  } ],
  "package_state" : [ {
    "product_name" : "OpenShift Developer Tools and Services",
    "fix_state" : "Affected",
    "package_name" : "jenkins",
    "cpe" : "cpe:/a:redhat:ocp_tools"
  }, {
    "product_name" : "OpenShift Developer Tools and Services",
    "fix_state" : "Affected",
    "package_name" : "jenkins-2-plugins",
    "cpe" : "cpe:/a:redhat:ocp_tools"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "javapackages-tools:201801/maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "maven:3.9/maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "maven-wagon",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  }, {
    "product_name" : "streams for Apache Kafka 2",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:amq_streams:2"
  }, {
    "product_name" : "streams for Apache Kafka 3",
    "fix_state" : "Not affected",
    "package_name" : "mina-core",
    "cpe" : "cpe:/a:redhat:amq_streams:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-47065\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-47065\nhttps://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj" ],
  "name" : "CVE-2026-47065",
  "csaw" : false
}